Gentoo Archives: gentoo-announce

From: Sean Amoss <ackle@g.o>
To: gentoo-announce@g.o
Subject: [gentoo-announce] [ GLSA 201412-20 ] GNUstep Base library: Denial of Service
Date: Sat, 13 Dec 2014 18:33:01
Message-Id: 548C8604.6030302@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201412-20
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: GNUstep Base library: Denial of Service
9 Date: December 13, 2014
10 Bugs: #508370
11 ID: 201412-20
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 A vulnerability in GNUstep Base library could lead to Denial of
19 Service.
20
21 Background
22 ==========
23
24 GNUstep Base library is a free software package implementing the API of
25 the OpenStep Foundation Kit (tm), including later additions.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 gnustep-base/gnustep-base
34 < 1.24.6-r1 >= 1.24.6-r1
35
36 Description
37 ===========
38
39 GNUstep Base library does not properly handle the file descriptor for
40 logging, when run as a daemon.
41
42 Impact
43 ======
44
45 A remote attacker could send a specially crafted request, possibly
46 resulting in a Denial of Service condition.
47
48 Workaround
49 ==========
50
51 There is no known workaround at this time.
52
53 Resolution
54 ==========
55
56 All GNUstep Base library users should upgrade to the latest version:
57
58 # emerge --sync
59 # emerge --ask --oneshot -v ">=gnustep-base/gnustep-base-1.24.6-r1"
60
61 References
62 ==========
63
64 [ 1 ] CVE-2014-2980
65 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-2980
66
67 Availability
68 ============
69
70 This GLSA and any updates to it are available for viewing at
71 the Gentoo Security Website:
72
73 http://security.gentoo.org/glsa/glsa-201412-20.xml
74
75 Concerns?
76 =========
77
78 Security is a primary focus of Gentoo Linux and ensuring the
79 confidentiality and security of our users' machines is of utmost
80 importance to us. Any security concerns should be addressed to
81 security@g.o or alternatively, you may file a bug at
82 https://bugs.gentoo.org.
83
84 License
85 =======
86
87 Copyright 2014 Gentoo Foundation, Inc; referenced text
88 belongs to its owner(s).
89
90 The contents of this document are licensed under the
91 Creative Commons - Attribution / Share Alike license.
92
93 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature